How we can drop transport event type in Elasticsearch 8.12 version

I am getting system generated log in Elasticsearch Audit logs file. can you please provide me solution to avoid the system generated logs in audit log.

I did below configuration in elasticsearch.yml file

[ec2-user@ip-172-31-39-77 ~]$ sudo su
[root@ip-172-31-39-77 ec2-user]# cat etc/elasticsearch/elasticsearch.yml
cat: etc/elasticsearch/elasticsearch.yml: No such file or directory
[root@ip-172-31-39-77 ec2-user]# cat /etc/elasticsearch/elasticsearch.yml

: true ["authentication_success","authentication_failed"] : true : true : true true true
Example of system generated audit log

{"type":"audit", "timestamp":"2024-01-31T13:01:05,961+0000", "cluster.uuid":"aqyZaw7QTgKfg0neAFQ1ig", "":"node-1", "":"6NN4AY_yRhqyXQ_9i4RQ-w", "":"", "host.ip":"", "event.type":"transport", "event.action":"authentication_success", "authentication.type":"INTERNAL", "":"_system", "user.realm":"__fallback", "origin.type":"local_node", "origin.address":"", "":"Xxi5qsZ5RzmrSAsjH9sS3Q", "action":"cluster:monitor/update/health/info", "":"Request"}

{"type":"audit", "timestamp":"2024-01-31T13:06:05,954+0000", "cluster.uuid":"aqyZaw7QTgKfg0neAFQ1ig", "":"node-1", "":"6NN4AY_yRhqyXQ_9i4RQ-w", "":"", "host.ip":"", "event.type":"transport", "event.action":"authentication_success", "authentication.type":"INTERNAL", "":"_system", "user.realm":"__fallback", "origin.type":"local_node", "origin.address":"", "":"tux-hSILReit31XuPnWNtg", "action":"cluster:monitor/update/health/info", "":"Request"}

You cannot (and should not) filter based on the event.type, you can add an ignore policy for particular user names

